针对轻型分组密码LED提出了一种基于碰撞模型的代数旁路攻击。利用代数攻击方法建立密码算法等效布尔代数方程组,采集算法运行中泄露的功耗信息并转换为碰撞信息,并将碰撞信息转换成额外方程组,从而利用CryptoMiniSAT解析器求解密钥。实验结果表明:旁路碰撞信息可有效降低方程组求解的复杂度;已知明文条件下,利用2轮最少50%的随机碰撞信息,即可在158.5 s内恢复64 bit LED完整密钥。此外,该方法也可用于其他分组密码功耗碰撞分析。
This paper proposed a collision model-based algebraic side-channel attack on lightweight block cipher LED.Firstly,it described the algebraic representations of LED.Secondly,it measured the power leakages of LED on ATMEGA324P microcontroller by a digital oscilloscope,and transformed to deduce collision.Finally,the collision was expressed as algebraic equations,and it applied the CryptoMiniSAT solver to solve for the key.Experiments demonstrate that the collision of side-channel information can introduce new algebraic equations into attack,reduce the complexity of solving equations;in the known-plaintext scenario,2 rounds collision information is enough to recover the 64 bit LED master key in 158.5 s.The proposed method can be applied into the collision-based power attack of other block ciphers.